You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 98e1664
Browse filesBrowse the repository at this point in the historyBrowse files
fix(oauth): refuse keyring indexes over the reader key cap on write
writeKeyIndex already refused over-cap chunk counts, but a large set of
short keys can stay under the chunk limit while exceeding
maxKeyringIndexKeys. Cap the key count before publishing so Save cannot
persist an index that readKeyIndex then rejects. Cover the write-side
path and multi-chunk accumulation on the reader.
// Refuse to publish an index the reader would reject: readKeyIndex caps both
864
+
// total keys and chunk count, and a header beyond either would make every
865
+
// later Load/Status/Save/Delete fail before it could recover. Check the key
866
+
// count before chunking so a large set of short keys that still fit under
867
+
// maxKeyringIndexChunks cannot strand the store unreadable.
868
+
iflen(keys) >maxKeyringIndexKeys {
869
+
return0, errKeyringIndexTooManyKeys(len(keys))
870
+
}
863
871
chunks:=chunkIndexKeys(keys)
864
-
// Refuse to publish an index the reader would reject: readKeyIndex caps
865
-
// headers at maxKeyringIndexChunks, and a header beyond it would make
866
-
// every later Load/Status/Save/Delete fail before it could recover.
867
872
iflen(chunks) >maxKeyringIndexChunks {
868
873
return0, fmt.Errorf("oauth: keyring key index needs %d chunks, over the %d-chunk cap readers accept; too many stored credentials", len(chunks), maxKeyringIndexChunks)
0 commit comments